Home / Docs Center / Platform API / API Reference

API Reference

Platform API · Account Integration

Project: Platform API | page_id: 98

Get channel name and secret key

Contact our staff to obtain the channel name channel and the secret key secret.
Request address: http://third.platform.xstrive.com

Signature rules (token generation)

  1. The signature uses md5 encryption to generate the token parameter, which is passed for verification.
  2. Build the string to be encrypted using the secret obtained in step 1.
  3. Sort the string by the lexicographical order of the URL parameters (if upper and lower case are tied, upper case comes first) and join them with &.
    Parameter sorting JS code example: keys = [key1,key2,...,secret,t]; keys = keys.sort();
    For other languages, please refer to their own API documentation.
    For example:
    http://third.platform.xstrive.com/product/online?channel=common&productId=test144&token=c054ddeb010a3c44427bd3a345aba1ee&t=1577587794
    String to be encrypted (all parameters except token):
    sign = channel=common&productId=test144&secret=df138a4ffa97d1f8fe41646670ccc842&t=1577587794
    After encryption: token = md5(sign) = c054ddeb010a3c44427bd3a345aba1ee

If the encrypted string matches the requested token, the signature verification passes.

Head Authorization

  1. auth type: Basic Auth
  2. Login and registration requests do not carry Head Authorization; those APIs use the signature rules only.
  3. After a successful login, the server issues an authentication token.
    For example:
    The authentication token obtained after a successful login is "testToken".
    Subsequent requests use Head Authorization = "Basic testToken".

Fixed parameters carried in requests

Parameter Description Type Required Additional Notes
channel Channel name String Y
token Signature string String Y
t Current timestamp Number Y Unit: seconds

After a successful login, refer to [Third-party Integration Documentation] for the parameters of subsequent APIs. The APIs are the same, except that they additionally require [Head Authorization].

Unified failure response JSON format

{
    "code": Number, // error code
    "msg": String   // error message
}

Example:

{
    "code":401,
    "msg":"Illegal request"
}
Didn't find what you need?Contact us,Talk to our engineers directly.

Request a Quote

Fill in the form and we will get back with a quote and proposal within 1 business day.

Click "Generate inquiry email" to open your mail client with the body pre-filled. If no mail client is configured, click "Copy" and paste it into webmail — recipient: sunshiyang@xstrive.com.